T08 · Insecure Dependencies
Warning
- Location
clawhub.json:4- Finding
Unpinned Third-Party Dependencies Expose the Skill to Supply-Chain Risk
- Content
View full analysis
- Remediation
View remediation
", "requests==" ] ``` 2. Use a lock file or requirements file containing cryptographic hashes and install with hash verification. 3. Obtain packages only from an explicitly configured, trusted package index. 4. Verify package ownership, release provenance, and signatures where the distribution mechanism supports them. 5. Run automated dependency vulnerability and provenance checks before releases. 6. Review and intentionally approve dependency updates rather than allowing automatic resolution to newly published versions. 7. Restrict the runtime environment so the process has only the filesystem, network, credential, and trading permissions required for this Skill. ]]>
